PHPWishList Unauthorized Administrator Access Vulnerability
BID:14202
Info
PHPWishList Unauthorized Administrator Access Vulnerability
| Bugtraq ID: | 14202 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2005 12:00AM |
| Updated: | Jul 07 2005 12:00AM |
| Credit: | The vendor is credited with the discovery of this vulnerability. |
| Vulnerable: |
phpWishlist phpWishlist 0.1.14 |
| Not Vulnerable: |
phpWishlist phpWishlist 0.1.15 |
Discussion
PHPWishList Unauthorized Administrator Access Vulnerability
phpWishList is prone to a vulnerability regarding the unauthorized access to administrator functions. This issue is due to a programming failure in the application to correctly set the $_SESSION variable.
This issue could be exploited to elevate privileges, this could aid in further attacks against the underlying system; other attacks are also possible.
phpWishList is prone to a vulnerability regarding the unauthorized access to administrator functions. This issue is due to a programming failure in the application to correctly set the $_SESSION variable.
This issue could be exploited to elevate privileges, this could aid in further attacks against the underlying system; other attacks are also possible.
Exploit / POC
PHPWishList Unauthorized Administrator Access Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
PHPWishList Unauthorized Administrator Access Vulnerability
Solution:
The vendor has addressed this issue in phpWishlist version 0.1.15.
Solution:
The vendor has addressed this issue in phpWishlist version 0.1.15.
References
PHPWishList Unauthorized Administrator Access Vulnerability
References:
References:
- phpWishlist Homepage (phpWishlist)